CVE-2024-13871: Bitdefender Box Firmware

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated, network-adjacent attacker to execute arbitrary commands on the device, potentially leading to full remote code execution (RCE).

Affected products

Published 2025-03-12. Last modified 2026-06-17.